首页> 外文OA文献 >Balancing Isolation and Sharing of Data for Third-Party Extensible App Ecosystems
【2h】

Balancing Isolation and Sharing of Data for Third-Party Extensible App Ecosystems

机译:平衡第三方可扩展应用程序的数据隔离和共享   生态系统

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

In the landscape of application ecosystems, today's cloud users wish topersonalize not only their browsers with various extensions or theirsmartphones with various applications, but also the various extensions andapplications themselves. The resulting personalization significantly raises theattractiveness for typical Web 2.0 users, but gives rise to various securityrisks and privacy concerns, such as unforeseen access to certain criticalcomponents, undesired information flow of personal information to untrustedapplications, or emerging attack surfaces that were not possible before apersonalization has taken place. In this paper, we propose a novel extensibility mechanism which is used forimplementing personalization of existing cloud applications towards (possiblyuntrusted) components in a secure and privacy-friendly manner. Our modelprovides a clean component abstraction, thereby in particular ruling outundesired component accesses and ensuring that no undesired information flowtakes place between application components -- either trusted from the baseapplication or untrusted from various extensions. We then instantiate our modelin the SAFE web application framework (WWW 2012), resulting in a novelmethodology that is inspired by traditional access control and specificallydesigned for the newly emerging needs of extensibility in applicationecosystems. We illustrate the convenient usage of our techniques by showing howto securely extend an existing social network application.
机译:在应用程序生态系统的前景中,当今的云用户不仅希望个性化其带有各种扩展程序的浏览器或具有各种应用程序的智能手机,而且还要个性化各种扩展程序和应用程序本身。个性化的结果大大提高了典型Web 2.0用户的吸引力,但引起了各种安全风险和隐私问题,例如无法预料地访问某些关键组件,不希望的个人信息流向不受信任的应用程序,或者出现了无法进行个性化之前出现的攻击面发生在。在本文中,我们提出了一种新颖的可扩展性机制,该机制用于以安全和隐私友好的方式对(可能不受信任的)组件实现现有云应用程序的个性化。我们的模型提供了干净的组件抽象,从而特别地排除了多余的组件访问,并确保在应用程序组件之间不会发生不希望的信息流-不受基础应用程序信任或不受各种扩展信任。然后,我们在SAFE Web应用程序框架中实例化模型(WWW 2012),从而产生了一种新颖的方法论,该方法论受到传统访问控制的启发,并专门针对应用程序生态系统中新出现的可扩展性需求而设计。我们通过展示如何安全地扩展现有社交网络应用程序来说明我们技术的便捷用法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号